IT225 Computer Security and Cyber Law

Computer Security and Cyber LawUnit 112 min read

Computer Security Fundamentals & Cyber Law Basics

Unit 1 of Computer Security and Cyber Law introduces core concepts like CIA triad, security threats, cyber law frameworks, and ethical principles in IT security, with real-world applications in Nepalese and global systems.

TAKEAWAYS:

  • Understand the CIA triad (Confidentiality, Integrity, Availability) as the foundation of all security policies.
  • Recognize human factors as both the weakest (social engineering) and strongest (security awareness) links in security.
  • Differentiate between cyber law (legal frameworks) and cyber ethics (moral guidelines) in digital environments.
  • Identify common security threats (malware, phishing, DoS) and their real-world impacts on businesses like eSewa or Ncell.
  • Apply security principles (least privilege, defense in depth) to design secure systems for e-commerce or banking apps.
  • Link cyber crimes (cyberbullying, identity theft) to legal consequences under Nepal’s Electronic Transactions Act, 2008.


1. Core Concepts of Computer Security

Computer security protects systems, networks, and data from unauthorized access, damage, or disruption. The CIA triad is its foundational model:

Prevents unauthorized access to dataExample: eSewa encrypts user transactionsConfidentialityEnsures data accuracy and consistencyExample: Bank transactions verified via digital signaturesIntegrityGuarantees system uptimeExample: Ncell’s 99.9% network reliabilityAvailabilityCIA Triad
Hierarchical breakdown of the CIA Triad with Nepali-relevant examples

Key Security Goals

Goal Definition Real-World Example
Confidentiality Restrict data access to authorized users only. Khalti uses end-to-end encryption for payment data.
Integrity Ensure data is accurate and unaltered. NEPSE validates stock trades to prevent fraud.
Availability Systems must operate reliably when needed. NTC’s fiber-optic backbone ensures internet availability during peak hours.
Authenticity Verify the identity of users/systems. Pathao uses OTPs to confirm driver identities.
Non-repudiation Prevent users from denying actions (e.g., transactions). Bank loans in Nepal require digital signatures to prove agreement.

2. Security Threats and Vulnerabilities

Threats exploit vulnerabilities in systems. Common types include:

011.2522.533.7545Phishing45Malware30Social Engineering15Insider Threats10
Percentage distribution of reported cyber incidents in Nepal (2022 data from Nepal Police Cyber Crime Unit)

A. Malware (Malicious Software)

types of malware labelled diagram**A flowchart showing malware categories with icons (virus, worm, trojan). (Image: Gelibnuira, CC BY-SA 4.0, via Wikimedia Commons)

B. Social Engineering

Humans are the weakest link. Examples:

  • Phishing: Fake emails (e.g., Ncell impersonation scams).
  • Pretexting: Fake identities (e.g., calling as "IT support" to steal credentials).
  • Baiting: Malicious USB drops (e.g., Daraz delivery scams with infected USBs).

Worked Example: A user receives an email from "support@esewa.com" asking to reset their password due to "suspicious login." Red Flags:

  1. Generic greeting ("Dear User").
  2. Link to a non-esewa.com domain (e.g., esewa-login[.]xyz).
  3. Urgency to act. Action: Report to eSewa’s official channel.

3. Cyber Law in Nepal

Nepal’s legal framework governs digital transactions and cyber crimes:

Law Year Key Provisions Example
Electronic Transactions Act 2008 Legal validity of digital signatures, e-contracts. Online loan agreements by banks must comply with this act.
Cyber Crime Act 2018 Punishes hacking, cyberbullying, identity theft. Ncell can sue hackers under this law for SIM-swapping fraud.
Right to Information Act 2011 Regulates data privacy and access to government databases. Citizens can request NTC’s data breach records under this act.
Intellectual Property Rights 2011 Protects software, digital content from piracy. Daraz sues sellers for counterfeit goods using this law.

4. Security Principles for System Design

Designing secure systems requires applying core principles:

A. Least Privilege

  • Definition: Users/systems get only the minimum access needed.
  • Example: A Daraz warehouse worker can scan items but not modify inventory records.
  • Violation Risk: If a worker’s account is hacked, damage is limited.

B. Defense in Depth

  • Definition: Layered security (e.g., firewalls + encryption + biometrics).
  • Example: Khalti’s security:
    1. Firewall (blocks DDoS).
    2. Encryption (protects data).
    3. Two-factor authentication (prevents credential theft).

C. Fail-Secure Defaults

  • Definition: Systems default to a secure state (e.g., locked doors, disabled ports).
  • Example: NTC’s routers are configured to block all traffic by default unless explicitly allowed.

5. Human Factors in Security

Humans are both the weakest (targets of social engineering) and strongest (security awareness) links.

  • Weak passwords: "123456" (used in 30% of breaches).
  • Phishing clicks: Ncell users lose Rs. 50M/year to SIM-swapping scams.
  • Public Wi-Fi risks: KFC’s free Wi-Fi in Nepal is often unencrypted.
2070 BSFirst recordedcybercrime case in Nep2075 BSRise of socialmedia scams (fake job 2078 BSWannaCryransomware attack on g
Major cybersecurity incidents timeline in Nepal with human factor connections
  • Training: Nepal Rastra Bank mandates cybersecurity training for bank employees.
  • Incident Reporting: eSewa rewards users who report phishing attempts.
  • Multi-Factor Authentication (MFA): Pathao drivers use fingerprint + OTP for app access.

Worked Example: A bank employee receives a call from someone claiming to be from "Nepal Rastra Bank IT Department," asking for their login credentials to "verify a fraudulent transaction." Steps to Handle:

  1. Verify the caller: Hang up and call the official bank helpline.
  2. Never share credentials: Even if pressured.
  3. Report the incident: Use the bank’s fraud reporting portal.

6. Common Security Programming Problems

Developers often introduce vulnerabilities. Four critical ones:

Problem Description Example in Nepal Fix
SQL Injection Malicious SQL queries exploit input fields. Daraz login page vulnerable to OR '1'='1 bypassing authentication. Use parameterized queries.
Cross-Site Scripting (XSS) Injects malicious scripts into web pages. eSewa forum posts stealing cookies via <script>. Sanitize user inputs and use Content Security Policy (CSP).
Buffer Overflow Exploits memory limits to crash or hijack systems. NTC’s old routers hacked via overflow attacks. Use safe coding languages (e.g., Rust) or bounds checking.
Insecure Direct Object References (IDOR) Accesses unauthorized data via URL manipulation. Pathao driver app allows URL changes to view other drivers’ earnings. Implement access control lists (ACLs).

7. Cyber Crimes and Ethical Issues

A. Cyber Crimes in Nepal

  1. Cyberbullying:

    • Definition: Harassment via digital media.
    • Example: Facebook groups targeting students with fake rumors.
    • Legal Action: Prosecuted under Cyber Crime Act, 2018 (up to 3 years jail).
  2. Identity Theft:

    • Example: Khalti accounts hacked to steal Rs. 2M in 2022.
    • Prevention: Use biometric authentication (fingerprint + PIN).
  3. Data Breaches:

    • Example: Ncell’s 2021 breach exposed 1M customer records.
    • Impact: Loss of trust, regulatory fines.

B. Ethical Dilemmas

  • Whistleblowing: Reporting a colleague’s security lapse vs. loyalty.
  • Privacy vs. Security: NTC monitoring internet traffic to prevent crimes but invading privacy.
  • Open-Source Risks: Using unpatched software (e.g., WordPress vulnerabilities).

## In the Real World

  1. eSewa’s Security:

    • Idea Used: Defense in Depth + Non-Repudiation.
    • How: Combines biometric login, transaction logs, and legal digital signatures to prevent fraud. When a user disputes a payment, eSewa’s logs act as evidence in court.
  2. Ncell’s SIM-Swapping Protection:

    • Idea Used: Multi-Factor Authentication (MFA).
    • How: Customers must enter an OTP sent to their registered email before changing SIM details, reducing fraud by 60% since 2021.
  3. Daraz’s Order Queue:

    • Idea Used: Integrity + Availability.
    • How: Uses blockchain-like ledgers to track orders and load balancers to ensure the website stays available during sales (e.g., Dashain discounts).
  4. Nepal Rastra Bank’s Cybersecurity:

    • Idea Used: Least Privilege + Incident Response.
    • How: Bank employees have role-based access (e.g., tellers can’t approve loans). In 2020, a breach was contained within 2 hours due to automated alerts.

## Exam Tip

  1. CIA Triad Questions:

    • Always explain how each goal is achieved (e.g., "Confidentiality is ensured via encryption like AES-256").
    • Example Answer:

      "For a bank like Nabil, confidentiality is maintained through TLS encryption for online transactions, access controls (e.g., role-based permissions), and data masking (e.g., hiding full card numbers)."

  2. Security Principles:

    • Link principles to real systems. For example:

      *"Defense in Depth is used by eSewa with:

      1. Firewall (blocks malicious IPs),
      2. End-to-end encryption (protects data in transit),
      3. Biometric authentication (prevents credential theft)."*
  3. Cyber Law:

    • Memorize key acts and their years (e.g., Electronic Transactions Act, 2008).
    • For definitions, use short, precise language:

      "Cyberbullying is the use of digital platforms to harass, threaten, or embarrass individuals, punishable under Section 28 of the Cyber Crime Act, 2018."

  4. Programming Problems:

    • Always give a fix. Examiners check if you know how to prevent vulnerabilities.
    • Example:

      "SQL Injection can be prevented by using prepared statements (e.g., in Python with `cursor.execute("SELECT * FROM users WHERE id = %s", (user_id,)))."

  5. Human Factors:

    • Balance weaknesses (e.g., phishing) with strengths (e.g., MFA training).
    • Example Answer:

      "Humans are the weakest link due to social engineering (e.g., Ncell scams), but also the strongest when trained in phishing simulations (e.g., Nepal Rastra Bank’s annual workshops)."

Based on the TU BITM syllabus for Computer Security and Cyber Law (IT225), unit 1.

Discussion

Loading…